CyberMax
Home › Glossary › Vulnerability management

What is CISA BOD 26-04?

Vulnerability management glossary · 1 primary source

CISA Binding Operational Directive 26-04, "Prioritizing Security Updates Based on Risk" (10 June 2026), which replaced BOD 22-01's flat KEV deadlines with risk-based timelines.

The directive scores each vulnerability on an agency asset with four decision points: whether the asset is publicly exposed, whether the CVE is in the KEV catalog, whether exploitation is automatable and the technical impact (the last two as documented by CISA's Vulnrichment programme). The combination sets the deadline; the most urgent tier is three days with forensic triage, and the lowest is "fix on system upgrade".

The clock starts when CISA adds the CVE to KEV or when the agency finds it on an asset, whichever comes first, and timelines move when exposure or KEV status changes. It binds federal civilian executive branch agencies; contractors only where their contract says so.

Sources

Related terms

On this site

All vulnerability management terms · Full glossary